Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deebot X1s Pro Firmware HIGH 7.2
CVE-2025-30199

ECOVACS vacuum robot base stations do not validate firmware updates, so malicious over-the-air updates can be sent to base station via insecure conne…

Fix: 1.11.0 / 2.4.45+
Fix from $1,950 2025-09-05
Deebot X1s Pro Firmware MEDIUM 6.3
CVE-2025-30198

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic WPA2-PSK, which can be easily derived.

Fix: 1.11.0 / 2.4.45+
Fix from $1,600 2025-09-05
Deebot X1s Pro Firmware MEDIUM 6.3
CVE-2025-30200

ECOVACS robot vacuums and base stations communicate via an insecure Wi-Fi network with a deterministic AES encryption key, which can be easily derive…

Fix: 1.11.0 / 2.4.45+
Fix from $1,600 2025-09-05
Deebot 900 Firmware HIGH 7.5
CVE-2024-52331

ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware updates. An attacker can create and encrypt malicious firm…

No fix yet
Fix from $1,950 2025-01-23
Home HIGH 7.4
CVE-2024-52329

ECOVACS HOME mobile app plugins for specific robots do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS tra…

Fix: 3.0.0+
Fix from $1,950 2025-01-23
Deebot X2 Omni Firmware HIGH 7.4
CVE-2024-52330

ECOVACS lawnmowers and vacuums do not properly validate TLS certificates. An unauthenticated attacker can read or modify TLS traffic, possibly modify…

Fix: 1.17.0 / 1.38.0+
Fix from $1,950 2025-01-23
Home MEDIUM 6.5
CVE-2024-52327

The cloud service used by ECOVACS robot lawnmowers and vacuums allows authenticated attackers to bypass the PIN entry required to access the live vid…

Fix: 3.0.2+
Fix from $1,600 2025-01-23
Deebot N10 Firmware MEDIUM 6.3
CVE-2024-12078

ECOVACS robot lawn mowers and vacuums use a shared, static secret key to encrypt BLE GATT messages. An unauthenticated attacker within BLE range can …

No fix yet
Fix from $1,600 2025-01-23
Deebot 900 Firmware HIGH 7.6
CVE-2024-11147

ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model and serial number. An attacker with shell access can …

No fix yet
Fix from $1,950 2025-01-23
Goat G1 2000 Firmware CRITICAL 9.6
CVE-2024-52325

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.

Fix: 1.2.120 / 1.36.187+
Fix from $2,300 2025-01-23